Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Use Content hub with Integrated Security Operations Center (ISOC) in Microsoft Defender to discover and install supported Microsoft Sentinel content for your ISOC workspace.
Note
During this preview, Content hub supports data connectors. If a solution includes multiple content types, only its data connectors are available for installation.
Prerequisites
Before you begin, make sure the following requirements are met:
- Your tenant is eligible for ISOC.
- You have an ISOC workspace.
- You have the following permissions:
- In Unified RBAC:
- Content hub read
- Content hub manage
- In Azure, Deploy permission on the resource group to install solutions.
- In Unified RBAC:
Discover content
Sign in to the Microsoft Defender portal.
Go to SIEM > Content management > Content hub.
Search for a solution or use the available filters to find content.
Select a solution to view its details and available data connectors.
Install data connectors
Sign in to the Microsoft Defender portal.
Go to SIEM > Content management > Content hub.
Search for and select the solution that contains the data connector you want to install.
Select View details.
Select Create.
On the Basics tab, select the subscription, resource group, and workspace where you want to deploy the solution.
Select Next to review the available configuration.
On the Review + create tab, wait for validation to complete.
Select Create.
Only supported data connectors from the solution are available for installation. Other content types included in the solution aren't installed during the ISOC preview.
After installation, configure the data connector to start ingesting data into your ISOC workspace.
Update an installed solution
If an installed solution has an available update, you can update it from Content hub.
Sign in to the Microsoft Defender portal.
Go to SIEM > Content management > Content hub.
Search for and select the installed solution.
Select View details.
Select Update.
Review the solution configuration.
Select Review + create.
Wait for validation to complete.
Select Update.
Note
During this preview, updates apply only to supported data connector content.